----- Original Message ----- From: "R. Scott Perry" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, July 02, 2003 3:40 PM Subject: Re: [Declude.Virus] Unknown Virus virus in Unknown File
> > >Hi, I have controlled and the file of report have qualified the relative > >option to the name of the virus. The antivirus ones that use is NetShield / > >McAfee, moreover this happens with all the types of virus, if you have need > >of other information are to disposition. Thanks for the attention and good > >job. > > For McAfee, you need to have "/REPORT report.txt" in the SCANFILE line in > the \IMail\Declude\virus.cfg file, and you also need to have a line "REPORT > Found". For example: > > SCANFILE C:\Progra~1\Common~1\networ~1\viruss~1\4.0.xx\scan.exe /ALL /NOMEM > /NOBEEP /NOBREAK /UNZIP /SILENT /NODDA /REPORT report.txt > VIRUSCODE 13 > REPORT Found > > (the SCANFILE line needs to be all on one line, starting with "SCANFILE" > and ending with "/REPORT report.txt"). > > -Scott > --- Hi Scott and thanks for the attention, you say to add me the option /report, but in past I have had problems when I inserted this option and in order to resolve these problems you advised me not to use /report, in bottom to mail you I bring back the content of mail that there are exchanges to you with respect to that problem, therefore what I must make. I can or I cannot add the option /report? thanks and good day. >Hello Scott, now works!!! I have eliminated the "/report" in the line of >command of scan.exe !!! I have made all the tests proposals from eicar and >it does not only come found a virus on the test: >To Test pre-scanning HTML >it is a problem? >indeed thanks you are always much available one :-) >----- Original Message ----- >From: "R. Scott Perry" <[EMAIL PROTECTED]> >To: "Salvatore Basso" <[EMAIL PROTECTED]> >Sent: Monday, October 07, 2002 3:40 PM >Subject: Re: HELO:Bad Code Installation > I believe I have found the problem. > > The log file shows that you have the scan.exe program create a report.txt > file. However, you have NOT told Declude that you are doing that -- you > should have a line "REPORT Found" in your \IMail\Declude\virus.cfg file. > > Since you do not have the "REPORT Found" line, Declude is expecting that if > there is no virus, there will be 1 file left in the directory (or 0 files > if a virus is found). When the eicar.com file is deleted by the on-access > virus scanner, it leaves the report.txt file, so there is 1 file left, and > Declude Virus reports that there is no virus (since it assumes that the one > file left is the only one that should be there, the eicar.com file). > -Scott > > At 08:46 AM 10/7/2002, you wrote: > >Hello Scott, thanks always for the aid ... the configuration is following: > > > >ver: 1.60 > >in the virus.cfg: > > > >ON ACCESS ON > > > >in the NetShield: > > > >Action: Move Infected files to a folderss > >Folder: c:\imail\spool\virus > > > >I send to you in attached the log generated as a result of a test carried > >out with eicar.com > >thanks. > > > > - Salvatore > > > > > >----- Original Message ----- > >From: "R. Scott Perry" <[EMAIL PROTECTED]> > >To: "Salvatore Basso" <[EMAIL PROTECTED]> > >Sent: Monday, October 07, 2002 2:22 PM > >Subject: Re: HELO:Bad Code Installation > > > > > > > > > > >Hello Scott, still thanks for your attention... you say me that not there > >is > > > >solution to my problem, but I would want to say you that with version > >1.26 > > > >he works "truly well" with this configuration: > > > > > > > >in the virus.cfg: > > > > > > > >ONACCESS ON > > > > > > > >in the NetShield: > > > > > > > >Action: Move Infected files to a folderss > > > >Folder: c:\imail\spool\virus > > > > > > > >Exclusion: nobody directory is excluded > > > > > > > >..... > > > >why with version 1.60 he does not work? thanks. > > > > > > This should work with v1.60 (although NetShield will not be able to report > > > the virus name when it detects a virus), as it did with v1.26. > > > > > > To get a better idea of what is happening, you can use the Declude debug > > > mode (using Declude Virus v1.60 with ONACCESS ON as you describe > > > above). To do this, change the "LOGLEVEL LOW" line in > > > \IMail\Declude\virus.cfg to "LOGLEVEL DEBUG". Then, send the test > > > eicar.com file through (using our Test Virus Sender at > > > http://www.declude.com/tools ), and then switch back to "LOGLEVEL LOW" > >(the > > > debug mode adds huge amounts of information to the log file). You can > >then > > > send me the \IMail\spool\vir####.log file (as an attachment), and I can > > > take a look at it to see what the problem may be. > > > -Scott --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
